Security
Some information deserves more than a folder.
We describe our security plainly. We don't claim certifications, audits or guarantees we haven't actually completed.

The short version
- Private by default.
- Encrypted in transit and at rest.
- You control what each person can ever see.
- Nothing releases automatically.
- A person reviews any estate access request.
Trust Centre
The detail behind each of those statements, including what isn't built yet.
Server-enforced authorization
Every record belongs to one Life Box. Access rules are enforced in the database and on the server, never by hiding buttons in the browser.
Private document storage
Documents are never stored at public web addresses. They are reached only through short-lived links tied to your signed-in account.
Stricter handling for passwords
Passwords, PINs and recovery codes are handled separately from the rest of your Life Box: encrypted, hidden by default, and kept out of notifications, analytics and ordinary search.
How you sign in
Today you sign in with an email address and password, or with Google. Multi-factor authentication and passkeys are being built and are not available yet.
Audit history
Sign-ins, will changes, changes to the people who can step in, permission changes, password reveals and exports are recorded and visible to you.
What Life Box decides, and what it never decides
Life Box organizes clear, low-risk information automatically and shows you what it did, so you can undo it. Anything important enough to affect people, authority or access waits for you. Life Box never decides who your executor is, who can step in, what gets released, or what happens to your passwords. Those always wait for you.
Nothing unlocks automatically
No one gets access because they know your email or say something happened. Every access request is reviewed by a person before anything is released.
Data residency
We prefer Canadian data residency where practical. We will not tell you your information never leaves Canada until every storage, backup, logging and processing provider has been verified.
You can leave with your data
You can download everything in your Life Box at any time. Your information stays yours.
How to verify what we say
Every security and privacy statement we publish is listed below with what actually backs it, who checked it and when. A statement is only marked Validated once a named person has confirmed it against the running system end to end. Anything that hasn't been through that check says so plainly — we would rather show the gap than imply an assurance we haven't earned.
Last validated: not yet — the first validation pass is in progress.
Every record belongs to one Life Box, and access rules are enforced in the database and on the server rather than in the browser.
Not yet validated/security
What backs it
Row-level security policies on every member table, plus server-side ownership checks inside each server function. Pending an independent review that attempts cross-account reads on every table and endpoint.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
Files are never stored at public URLs. Documents are reached only through short-lived signed links tied to your signed-in account.
Not yet validated/security · /privacy
What backs it
Documents live in a private storage bucket; the app issues time-limited signed URLs on request. Pending a check that no bucket is publicly listable and that expired links are refused.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
Passwords, PINs and recovery codes are a separate item type — hidden by default, revealed intentionally, and kept out of analytics, notifications and ordinary AI indexing.
Not yet validatedEncryption keys are held by Life Box on the server. This is not zero-knowledge or end-to-end encryption, and we don't describe it as either.
/security
What backs it
Stored secrets are sealed with AES-256-GCM and unsealed only inside an authenticated server function for the owner of the record. Pending a check of every analytics, notification and AI code path for leakage.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
Your information is encrypted in transit and while stored.
Not yet validatedEncryption at rest is provider-managed with keys held on our side of the service, not derived from your password.
/privacy · /legal
What backs it
HTTPS for all traffic; storage and database encryption at rest provided by our infrastructure provider. Pending written confirmation from each provider covering primary storage, replicas, backups and logs.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
Today you sign in with an email address and password, or with Google. Multi-factor authentication and passkeys are being built and are not available yet.
Planned/security
What backs it
Email/password with verification and Google sign-in are live. Multi-factor authentication, passkeys and a session manager are on the roadmap and are described as future work, not current capability.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
Consequential actions — sign-ins, will changes, representative changes, permission changes, secret reveals and exports — are recorded as immutable audit events.
Not yet validated/security
What backs it
Audit events are written to an append-only table with no update or delete policy. Pending a review confirming every listed action writes an event and that no role can amend history.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
No one gets access because they know your email, claim you died, or upload a copy of a will. Every access claim is reviewed by a person.
Not yet validated/security · /legal
What backs it
Access claims enter a request queue and release nothing until a Life Box reviewer approves specific items. There is no automatic unlock path in the code. Pending a documented review procedure and an end-to-end rehearsal of a real claim.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
We prefer Canadian data residency where practical, and we won't tell you your data never leaves Canada until every vendor has been verified.
Not yet validatedUntil that mapping is finished and published here, treat Canadian residency as an intention rather than a guarantee.
/security
What backs it
Vendor-by-vendor mapping of storage, backups, authentication, email, logging, telemetry, analytics, support tooling and AI processing is not yet complete.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
Life Box reads the documents you upload to suggest categories, people, dates and other facts, which you then confirm or dismiss.
Not yet validatedBecause documents are processed, we do not claim that AI never sees your files. AI can make mistakes; your original documents remain authoritative.
/privacy
What backs it
Uploaded document text is sent to our AI provider for extraction; nothing is applied to your Life Box without your confirmation. Pending published detail on which processor receives the text, where it runs, what is retained and whether it is excluded from model training.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
We do not sell your personal information or use your stored content for advertising.
Not yet validated/privacy · /legal
What backs it
No advertising, data-brokerage or profiling integration exists in the product, and stored content is used only to deliver features you ask for. Pending a documented vendor review confirming no downstream vendor does so either.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026
Export your Life Box at any time. Portability is part of the trust model.
Not yet validated/security · /legal
What backs it
A full CSV export covering items, documents, accounts, people, representatives and messages is available in the app. Pending a check that the export is complete against a populated account.
- Last validated
- —
- Validated by
- —
- Next review
- September 30, 2026